BSCP Exam Prep & Study Resources
PortSwigger certification · 2 products
Burp Suite Certified Exam
Study materials for BSCP

Burp Suite Certified Practitioner
A fast-paced, hands-on web application security exam focused on deep mastery of Burp Suite. You get 4 hours to attack two vulnerable applic…
$199$250
View →
Burp Suite Certified Practitioner
A fast-paced, hands-on web application security exam focused on deep mastery of Burp Suite. You get 4 hours to attack two vulnerable applic…
$99$170
View →Frequently asked questions
What is the BSCP certification?
The Burp Suite Certified Practitioner (BSCP) is a web security certification from PortSwigger, the creators of Burp Suite. It validates practical web application security testing skills using Burp Suite Professional. The certification is unique in that it comes directly from the vendor of the most widely used web application testing tool in the industry, ensuring deep alignment between the exam content and real-world Burp Suite usage.
How hard is the BSCP exam?
BSCP is moderately challenging and requires strong practical web security skills. The exam is a four-hour practical assessment where candidates must exploit web vulnerabilities in live applications using Burp Suite. Candidates need solid understanding of common web vulnerabilities and fluency with Burp Suite's features including the scanner, repeater, intruder, and extensions. Those who have completed the PortSwigger Web Security Academy labs thoroughly are well prepared for the exam format and difficulty level.
What topics does BSCP cover?
BSCP covers a broad range of web security testing topics aligned with PortSwigger's Web Security Academy curriculum. These include SQL injection, cross-site scripting, CSRF, CORS misconfiguration, clickjacking, DOM-based vulnerabilities, WebSocket vulnerabilities, server-side request forgery, HTTP request smuggling, OAuth vulnerabilities, JWT attacks, prototype pollution, and web cache poisoning. The exam focuses on practical exploitation using Burp Suite as the primary testing tool.
How does BSCP compare to OSWE?
BSCP and OSWE target different aspects of web security testing. OSWE focuses on white-box source code analysis and developing custom exploits, requiring strong programming skills and access to application source code. BSCP focuses on black-box web application testing using Burp Suite, emphasizing the ability to find and exploit vulnerabilities through external testing. BSCP is more accessible and directly applicable to everyday web penetration testing, while OSWE covers deeper, code-level exploitation.
How long does it take to prepare for BSCP?
Most candidates spend one to three months preparing for BSCP. The PortSwigger Web Security Academy provides free, comprehensive preparation material with hundreds of interactive labs covering every topic on the exam. Candidates who complete all relevant Web Security Academy labs are generally well prepared. Those with existing web penetration testing experience may need less time, while newcomers to web security should plan for the longer end of the preparation window.
What are the prerequisites for BSCP?
There are no formal prerequisites, but candidates need a Burp Suite Professional license to take the exam. Practical experience with web application security testing and familiarity with Burp Suite's core features are essential. Candidates should be comfortable with HTTP fundamentals, web application architecture, and common vulnerability classes. Completing the PortSwigger Web Security Academy practitioner-level labs is the recommended preparation path.
Is BSCP worth it?
BSCP is particularly valuable for web application penetration testers and security consultants who use Burp Suite as their primary tool. As a vendor certification from PortSwigger, it demonstrates deep proficiency with the industry's most popular web testing platform. The certification is growing in recognition within the security community. The relatively low cost and the availability of free preparation through Web Security Academy make it an excellent return on investment for web security professionals.
What is the BSCP exam format?
The BSCP exam is a four-hour proctored practical assessment. Candidates are presented with two live web applications, each containing multiple vulnerabilities that must be discovered and exploited in sequence to achieve specific objectives. The exam requires Burp Suite Professional and tests the ability to chain vulnerabilities together to achieve meaningful impact. No report writing is required, only successful exploitation demonstrated through achieving the exam objectives.
What study resources help with BSCP preparation?
The PortSwigger Web Security Academy is the single best preparation resource and is completely free. It includes detailed topic explanations and hundreds of interactive labs for every vulnerability category tested on the exam. Additional helpful resources include the Burp Suite documentation, PortSwigger blog posts on advanced techniques, and community write-ups of Web Security Academy lab solutions. Practicing with Burp Suite Professional daily to build tool familiarity is essential.
What is the cost and retake policy for BSCP?
The BSCP exam costs $99 USD per attempt, making it one of the most affordable practical web security certifications available. A Burp Suite Professional license is required separately. Failed attempts can be retried by purchasing another exam voucher, and there is a short waiting period between attempts. The low exam cost combined with free preparation through Web Security Academy makes BSCP exceptionally accessible compared to other web security certifications.